OSL

Early access. OSL is being built toward its v1 launch, so some of what you see here is still being finished.

See what works today

Getting started with OSL

Install OSL, set your password, and send your first encrypted message.

Install OSL #

Download OSL from the download page and run the installer.

On first launch, Windows may show a SmartScreen warning that says "Windows protected your PC." This is expected because OSL is a new application from an independent developer. Click "More info" and then "Run anyway." See the explanation on the download page for the full story.

OSL opens as its own desktop hub. Connector availability changes during the beta, so the app shows which social and email services can be linked in your installed release.

Set your password #

During setup, OSL asks for a main password and shows separate recovery material. In the reviewed source, the Hub identity path uses a persistent TPM or operating-system credential-store sealer, accepted message-store values are sealed before SQLite writes, and the main-password file-storage key conditionally seals some JSON files. This is not whole-profile encryption: some JSON, Hub configuration, renderer localStorage, provider-managed profiles, the active-slot marker, and a fixed-label startup trace can remain plaintext. These are source and focused-test findings, not a named-release guarantee.

Write your password down somewhere safe. A password manager works. A piece of paper in a drawer works. What doesn't work is "I'll remember it."

Whitelist your first friend #

Both you and your friend need OSL installed to exchange encrypted messages. After both of you have OSL running, you can whitelist each other.

To whitelist someone, click their name in any channel to open their profile, then click "Whitelist for OSL." Once they whitelist you back, encryption is enabled between you.

For bulk whitelisting in a server or channel, right-click the channel header's lock icon and choose "Whitelist channel members."

Send your first encrypted message #

Open a supported conversation, choose OSL Protected, and type in the trusted OSL composer. OSL encrypts the message before giving the sealed carrier to the connected service.

Your friend, also running OSL, sees the message opened locally. Anyone reading the raw stored service message sees ciphertext only.

What if your friend doesn't have OSL? #

If you send an encrypted message to someone without OSL, they'll see what looks like random base64 garbage. That is the ciphertext, and it cannot be decrypted without OSL and the right keys.

You have two options: install OSL together with them, or send them an unencrypted message by clicking the lock icon to temporarily disable encryption for that message.

You'll get a clear visual indicator before sending an unencrypted message so it doesn't happen by accident.